google / google/osv-scanner

Display severity using ecosystem-specific priority tags

Open
#1,275 0 comments 0 reactions 1 assignee Claimed by @G-Rath View on GitHub
enhancement
Dominant language
Go
Stars
11k
Forks
792
Avg merge
1d 20h
Merged PRs (30d)
48

Description

Linux distros like Ubuntu have their own priority tag (e.g., "[ubuntu_priority](https://ubuntu.com/security/cves/about#priority)": "medium") indicating the impact of each vulnerability. This priority is based on many factors, including severity, importance, risk, and so on. This may be more accurate for users to identify the importance of each vulnerability than CVSS scores.

result from OSV-Scanner:
![image](https://github.com/user-attachments/assets/cb166a32-1658-482b-98f8-37407e357519)
The ubuntu priority:
![image](https://github.com/user-attachments/assets/4527dedd-d783-4860-a580-542ff534acba)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.